CVE-2024-0670
Privilege escalation in windows agent
- Published
- Mar 11, 2024
- Updated
- Feb 13, 2025
- Assigning CNA
- Checkmk
- Evidence observed
- Aug 8, 2026
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HLow · next 30 days
- Percentile
- 26.5%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
Privilege escalation in windows agent plugin in Checkmk before 2.2.0p23, 2.1.0p40 and 2.0.0 (EOL) allows local user to escalate privileges
Sources
7This repository contains an exploit demonstration for CVE-2024-0670, a local privilege escalation vulnerability affecting the CheckMK Agent for Windows. The vulnerability allows a low-privileged user to obtain SYSTEM privileges by abusing writable file paths processed by the MSI repair mechanism.
PoC for CVE-2024-0670
- HTB-NanoCorp-CVE-2024-0670Exploit
PowerShell exploit for CVE-2024-0670 that abuses CheckMK Agent MSI repair to escalate privileges to SYSTEM on the NanoCorp Hack The Box machine.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.